|
|
| |
|
| |
pulseaudio: privilege escalation
| Package(s): | pulseaudio |
CVE #(s): | CVE-2009-1894
|
| Created: | July 16, 2009 |
Updated: | July 28, 2009 |
| Description: |
PulseAudio has a local privilege escalation vulnerability.
From the Gentoo alert:
Tavis Ormandy and Julien Tinnes of the Google Security Team discovered
that the pulseaudio binary is installed setuid root, and does not drop
privileges before re-executing itself. The vulnerability has
independently been reported to oCERT by Yorick Koster.
A local user who has write access to any directory on the file system
containing /usr/bin can exploit this vulnerability using a race
condition to execute arbitrary code with root privileges. |
| Alerts: |
|
( Log in to post comments)
|
|
|